Remediation
From Azure Portal
-
Go to
Microsoft Entra ID. -
Under
Monitoring, clickDiagnostic settings. -
Click
+ Add diagnostic setting. -
Provide a
Diagnostic setting name. -
Under
Logs > Categories, check the box next to each of the following logs:AuditLogsSignInLogsNonInteractiveUserSignInLogsServicePrincipalSignInLogsManagedIdentitySignInLogsProvisioningLogsADFSSignInLogsRiskyUsersUserRiskEventsNetworkAccessTrafficLogsRiskyServicePrincipalsServicePrincipalRiskEventsEnrichedOffice365AuditLogsMicrosoftGraphActivityLogsRemoteNetworkHealthLogsNetworkAccessAlerts
-
Configure an appropriate destination for the logs.
-
Click
Save.